Addonspress maintains a narrowly scoped WordPress plugin portfolio centered on data import functionality through its Advanced Import product. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Addonspress over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-4328MEDIUM The Advanced Import plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.4.6. This is due to the plugin using wp_remote_get() t | Jun 19, 2026 | 6.4 | 26 | NO | NO |
CVE-2022-3677MEDIUM The Advanced Import WordPress plugin before 1.3.8 does not have CSRF check when installing and activating plugins, which could allow attackers to make a logged in admin install arb | Dec 5, 2022 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Addonspress.
Media articles that mention a CVE ID that affects a product developed by Addonspress — matched by CVE ID, not by vendor name.